Описание
A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220196.
Ссылки
- ExploitIssue Tracking
- Permissions RequiredThird Party Advisory
- Permissions RequiredThird Party Advisory
- ExploitIssue Tracking
- Permissions RequiredThird Party Advisory
- Permissions RequiredThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:xuxueli:xxl-job:2.3.1:*:*:*:*:*:*:*
EPSS
Процентиль: 22%
0.00071
Низкий
4.3 Medium
CVSS3
6.5 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
EPSS
Процентиль: 22%
0.00071
Низкий
4.3 Medium
CVSS3
6.5 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-352